« Volver al listado

CVE-2025-68475

Estado: AnalizadaAlta (7.5)—

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad ReDoS en regex de parseador HTML expuesto en servicio ActivityPub remoto (AV:N, PR:N); impacto DoS por agotamiento de CPU mediante entrada maliciosa.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68475",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-68475",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-22T21:54:29.525857Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "fedify-dev",
          "product": "fedify",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.6.13"
            },
            {
              "status": "affected",
              "version": ">= 1.7.0, < 1.7.14"
            },
            {
              "status": "affected",
              "version": ">= 1.8.0, < 1.8.15"
            },
            {
              "status": "affected",
              "version": ">= 1.9.0, < 1.9.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-22T22:16:09.143",
  "references": [
    {
      "url": "https://github.com/fedify-dev/fedify/commit/2bdcb24d7d6d5886e0214ed504b63a6dc5488779",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/commit/bf2f0783634efed2663d1b187dc55461ee1f987a",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/releases/tag/1.6.13",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/releases/tag/1.7.14",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/releases/tag/1.8.15",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/releases/tag/1.9.2",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/fedify-dev/fedify/security/advisories/GHSA-rchf-xwx2-hm93",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1333"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains nested quantifiers that cause catastrophic backtracking when processing maliciously crafted HTML responses. This issue has been patched in versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2."
    },
    {
      "lang": "es",
      "value": "Fedify es una biblioteca de TypeScript para construir aplicaciones de servidor federadas impulsadas por ActivityPub. Versiones anteriores a las versiones 1.6.13, 1.7.14, 1.8.15 y 1.9.2, existe una vulnerabilidad de denegación de servicio por expresión regular (ReDoS) en el cargador de documentos de Fedify. La expresión regular de análisis HTML en packages/fedify/src/runtime/docloader.ts:259 contiene cuantificadores anidados que causan retroceso catastrófico al procesar respuestas HTML maliciosamente elaboradas. Este problema ha sido parcheado en las versiones 1.6.13, 1.7.14, 1.8.15 y 1.9.2."
    }
  ],
  "lastModified": "2026-09-28T10:10:00.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fedify:fedify:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F097114-F157-4FE4-9CB8-2BAA384C5B30",
              "versionEndExcluding": "1.6.13"
            },
            {
              "criteria": "cpe:2.3:a:fedify:fedify:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9267FB8-A2C3-4269-A895-703ACA0C7078",
              "versionEndExcluding": "1.7.14",
              "versionStartIncluding": "1.7.0"
            },
            {
              "criteria": "cpe:2.3:a:fedify:fedify:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9EE0DA7-B892-4C34-B4F6-9B413A1A896F",
              "versionEndExcluding": "1.8.15",
              "versionStartIncluding": "1.8.1"
            },
            {
              "criteria": "cpe:2.3:a:fedify:fedify:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CEFCAFFE-AFCB-468E-8F32-63B8205A39DA",
              "versionEndExcluding": "1.9.2",
              "versionStartIncluding": "1.9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}